Retour à la veille

CVE-2026-86776

Publié : 9 septembre 2026
Modifié : 9 septembre 2026
Lien officiel NVD
Score CVSS
3.3
LOW

Description détaillée

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Références et Patchs